1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
  1. Guard
  2. Security
  3. CVEs
HOL Guard

Public security guidance for teams protecting AI harnesses, MCP servers, skills, prompts, and local tool execution.

Install Guard

AI Security

  • Prompt injection
  • MCP security
  • Supply chain

Resources

  • Trust packet
  • Harness setup
  • Redacted warnings
  • Safe labs

Product

  • Install Guard
  • Pricing
  • Open dashboard
HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

HOL LogoHOL
Overview
InstallPricingEnterpriseAffiliatesDocsOpen App
Docs
  • API Reference
  • Run in Postman
  • OpenAPI Spec
  • Standards
  • Submit ERC-8004 Contract
  • Feature Your Agent
Best Agents
  • Best ERC-8004 Agents
  • Best Virtuals Agents
  • Best MCP Servers
  • Best A2A Agents
  • Best x402 Payable
  • All Categories
Community
  • Telegram
  • X
More
  • Blog
  • GitHub
  • Privacy Policy
  • Terms of Service
Settings

Copyright © 2026 HOL DAO LLC. All rights reserved.

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 9, 2026, 11:25 AM 16,326 active 1,443 known exploited

Catalog summary

16,326

Active CVEs

Active CVEs

Search active, non-withdrawn CVEs in the HOL Guard feed, then open the matching HOL analysis.

Feed liveLast checked Aug 9, 2026, 11:25 AM 16,326 active 1,443 known exploited

Catalog summary

16,326

Active CVEs

8,448

Critical + high

1,443

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 2,951–3,000 of 16,326 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-33445High
    Memory management vulnerability in Secure Access servers
    CVSS 8.7
    Absolute Security/Secure Accessgeneric
    PublishedJul 15, 2026First seen at HOL Jul 15, 2026Updated Jul 16, 2026 Fix availableView HOL analysis
  2. CVE-2026-33444Medium
    Memory management vulnerability in Secure Access servers
    CVSS 6.9
    Absolute Secutity/Secure Accessgeneric
    PublishedJul 15, 2026First seen at HOL Jul 15, 2026Updated Jul 16, 2026 Fix availableView HOL analysis
  3. CVE-2026-33443High
    Memory management error in Secure Access servers prior to 14.55
    CVSS 7.1
    Absolute Security/Secure Accessgeneric
    PublishedJul 15, 2026First seen at HOL Jul 15, 2026Updated Jul 16, 2026 Fix availableView HOL analysis
  4. CVE-2026-40958Low
    Input validation error in Secure Access clients prior to 14.55
    CVSS 3.7
    Absolute Security/Secure Accessgeneric
    PublishedJul 15, 2026First seen at HOL Jul 15, 2026Updated Jul 16, 2026 Fix availableView HOL analysis
  5. CVE-2026-45737Medium
    Argo CD: Kubernetes Secret Extraction via ArgoCD ServerSideDiff via sensitive annotations
    CVSS 6.3
    argoproj/argo-cd, github.com/argoproj/argo-cd +2generic · go
    PublishedJul 15, 2026First seen at HOL Jul 15, 2026Updated Jul 20, 2026 Fix availableView HOL analysis
  6. CVE-2026-40957High
    Frameable content vulnerability in the Secure Access server login page
    CVSS 7.5
    Absolute Security/Secure Accessgeneric
    PublishedJul 15, 2026First seen at HOL Jul 15, 2026Updated Jul 16, 2026 Fix availableView HOL analysis
  7. CVE-2026-40956Low
    Memory disclosure in Secure Access Clients
    CVSS 3.7
    Absolute Security/Secure Accessgeneric
    PublishedJul 15, 2026First seen at HOL Jul 15, 2026Updated Jul 16, 2026 Fix availableView HOL analysis
  8. CVE-2026-45738High
    Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation
    CVSS 7.3
    argoproj/argo-cdgeneric
    PublishedJul 15, 2026First seen at HOL Jul 15, 2026Updated Jul 16, 2026View HOL analysis
  9. CVE-2026-40955Low
    Integer underflow vulnerability in Secure Access clients
    CVSS 3.7
    Absolute Security/Secure Accessgeneric
    PublishedJul 15, 2026First seen at HOL Jul 15, 2026Updated Jul 16, 2026 Fix availableView HOL analysis
  10. CVE-2026-40954Low
    Integer underflow in Secure Access clients prior to 14.55
    CVSS 3.7
    Absolute Security/Secure Accessgeneric
    PublishedJul 15, 2026First seen at HOL Jul 15, 2026Updated Jul 16, 2026 Fix availableView HOL analysis
  11. CVE-2026-46684Critical
    DataEase: Unauthorized Command Execution Vulnerability
    CVSS 9.5
    dataease/dataeasegeneric
    PublishedJul 15, 2026First seen at HOL Jul 15, 2026Updated Jul 17, 2026View HOL analysis
  12. CVE-2026-40953Medium
    Heap overflow in Secure Access clients
    CVSS 6.7
    Absolute Security/Secure Accessgeneric
    PublishedJul 15, 2026First seen at HOL Jul 15, 2026Updated Jul 16, 2026 Fix availableView HOL analysis
  13. CVE-2026-45320High
    DataEase Data Dashboard SqlVariable transFilter Unfiltered SQL Injection
    CVSS 8.7
    dataease/dataeasegeneric
    PublishedJul 15, 2026First seen at HOL Jul 15, 2026Updated Jul 17, 2026View HOL analysis
  14. CVE-2026-45535High
    DataEase: Stored SQL Injection Vulnerability
    CVSS 8.7
    dataease/dataeasegeneric
    PublishedJul 15, 2026First seen at HOL Jul 15, 2026Updated Jul 16, 2026View HOL analysis
  15. CVE-2026-45533High
    DataEase: Path Traversal Vulnerability
    CVSS 8.3
    dataease/dataeasegeneric
    PublishedJul 15, 2026First seen at HOL Jul 15, 2026Updated Jul 17, 2026View HOL analysis
  16. CVE-2026-40952High
    Privilge misconfiguration in Secure Access installers
    CVSS 8.5
    Absolute Security/Secure Accessgeneric
    PublishedJul 15, 2026First seen at HOL Jul 15, 2026Updated Jul 16, 2026 Fix availableView HOL analysis
  17. CVE-2026-45419High
    DataEase: Arbitrary File Write Vulnerability
    CVSS 8.5
    dataease/dataeasegeneric
    PublishedJul 15, 2026First seen at HOL Jul 15, 2026Updated Jul 18, 2026View HOL analysis
  18. CVE-2026-45417High
    DataEase: SQL injection vulnerability
    CVSS 8.7
    dataease/dataeasegeneric
    PublishedJul 15, 2026First seen at HOL Jul 15, 2026Updated Jul 16, 2026View HOL analysis
  19. CVE-2026-45534Critical
    DataEase: RCE Vulnerability
    CVSS 9.0
    dataease/dataeasegeneric
    PublishedJul 15, 2026First seen at HOL Jul 15, 2026Updated Jul 16, 2026View HOL analysis
  20. CVE-2026-15895High
    OS command injection in jsii-diff in AWS jsii
    CVSS 7.8
    AWS/jsii, jsii-diffgeneric · npm
    PublishedJul 15, 2026First seen at HOL Jul 15, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  21. CVE-2026-46421Critical
    Supply chain compromise via malicious package versions (@cap-js/sqlite, @cap-js/postgres, @cap-js/db-service)
    CVSS 9.3
    @cap-js/db-service/@cap-js/db-service, cap-js/@cap-js/postgres +1generic
    PublishedJul 15, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  22. CVE-2026-26032Medium
    Apache Ivy: PackagerResolver path traversal vulnerability
    CVSS 5.4
    Apache Software Foundation/Apache Ivygeneric
    PublishedJul 15, 2026First seen at HOL Jul 15, 2026Updated Jul 16, 2026View HOL analysis
  23. CVE-2026-15746Medium
    Credential disclosure in Strands Agents Tools elasticsearch_memory tool
    CVSS 6.5
    Amazon/strands-agents-toolsgeneric
    PublishedJul 15, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  24. CVE-2026-12997High
    Gravity Forms <= 2.10.4 - Unauthenticated Arbitrary File Read via 'gform_uploaded_files' Parameter
    CVSS 7.5
    Gravity Forms/Gravity Formsgeneric
    PublishedJul 15, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  25. CVE-2026-46485High
    Dash: Users can write to config despire permissions (OIDC tested)
    CVSS 8.2
    lissy93/dashygeneric
    PublishedJul 15, 2026First seen at HOL Jul 15, 2026Updated Jul 20, 2026View HOL analysis
  26. CVE-2026-40501High
    Cherry Studio RCE via SearchService nodeIntegration Misconfiguration
    CVSS 8.8
    CherryHQ/cherry-studiogeneric
    PublishedJul 15, 2026First seen at HOL Jul 15, 2026Updated Jul 28, 2026View HOL analysis
  27. CVE-2026-10673High
    Out-of-bounds write in ADIN2111/ADIN1110 OA SPI Ethernet RX frame reassembly
    CVSS 8.3
    zephyrproject/zephyrgeneric
    PublishedJul 15, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  28. CVE-2026-12382High
    Aap-gateway: missing requestheaderstoremove allows mtls bypass via subject header spoofing
    CVSS 8.2
    Affected software not mappedEcosystem not listed
    PublishedJul 15, 2026First seen at HOL Jul 15, 2026Updated Jul 21, 2026View HOL analysis
  29. CVE-2026-20298Medium
    Sensitive Information Disclosure through the storage/passwords REST Endpoint in Splunk Enterprise
    CVSS 5.3
    Splunk/Splunk Cloud Platform, Splunk/Splunk Enterprisegeneric
    PublishedJul 15, 2026First seen at HOL Jul 16, 2026Updated Jul 16, 2026 Fix availableView HOL analysis
  30. CVE-2026-20296High
    SPL Command Safeguards Bypass through Cross-Site Request Forgery (CSRF) in Deployment Server in Splunk Enterprise
    CVSS 8.3
    Splunk/Splunk Cloud Platform, Splunk/Splunk Enterprisegeneric
    PublishedJul 15, 2026First seen at HOL Jul 15, 2026Updated Jul 16, 2026 Fix availableView HOL analysis
  31. CVE-2026-20297High
    Path Traversal through 'explicit_appname' in the App Install REST Endpoint in Splunk Enterprise
    CVSS 7.2
    Splunk/Splunk Cloud Platform, Splunk/Splunk Enterprisegeneric
    PublishedJul 15, 2026First seen at HOL Jul 15, 2026Updated Jul 16, 2026 Fix availableView HOL analysis
  32. CVE-2026-14961Medium
    CVE-2026-14961
    CVSS 6.2
    Pegatron Corp./Tdelo64.sysgeneric
    PublishedJul 15, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  33. CVE-2026-14960Critical
    CVE-2026-14960
    CVSS 9.8
    Pegatron Corp./Tdelo64.sysgeneric
    PublishedJul 15, 2026First seen at HOL Jul 15, 2026Updated Jul 16, 2026View HOL analysis
  34. CVE-2026-1563Medium
    Pega Platform versions 8.1.0 through 25.1.2 are affected by an Reflected Cross-site scripting (XSS) vulnerability in a user interface component. Requires a high privileged user with a developer role.
    CVSS 4.8
    Pegasystems/Pega Infinitygeneric
    PublishedJul 15, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  35. CVE-2026-1562Medium
    Pega Platform versions 8.1.0 through 25.1.2 are affected by an Stored Cross-site scripting (XSS) vulnerability in a user interface component. Requires a high privileged user with a developer role.
    CVSS 4.6
    Pegasystems/Pega Infinitygeneric
    PublishedJul 15, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  36. CVE-2026-45793High
    Composer: Github Actions issued GITHUB_TOKEN disclosure in GitHub Actions logs
    CVSS 7.5
    composer/composergeneric
    PublishedJul 15, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  37. CVE-2026-20187High
    Cisco RoomOS Security Hardening Release - Exceptional Conditions Handling Vulnerabilities
    CVSS 7.5
    Cisco/Cisco RoomOS Softwaregeneric
    PublishedJul 15, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  38. CVE-2026-20158High
    Cisco RoomOS Security Hardening Release - Resource Lifetime Management Vulnerabilities
    CVSS 7.5
    Cisco/Cisco RoomOS Softwaregeneric
    PublishedJul 15, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  39. CVE-2026-20153High
    Cisco RoomOS Security Hardening Release - Input Validation Vulnerabilities
    CVSS 7.5
    Cisco/Cisco RoomOS Softwaregeneric
    PublishedJul 15, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  40. CVE-2026-20157High
    Cisco RoomOS Security Hardening Release - Missing Encryption Vulnerabilities
    CVSS 7.5
    Cisco/Cisco RoomOS Softwaregeneric
    PublishedJul 15, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  41. CVE-2026-20156High
    Cisco RoomOS Security Hardening Release - Buffer Management Vulnerabilities
    CVSS 8.1
    Cisco/Cisco RoomOS Softwaregeneric
    PublishedJul 15, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  42. CVE-2026-20146Medium
    Cisco Identity Services Engine Path Traversal Vulnerability
    CVSS 5.5
    Cisco/Cisco ISE Passive Identity Connector, Cisco/Cisco Identity Services Engine Softwaregeneric
    PublishedJul 15, 2026First seen at HOL Jul 15, 2026Updated Jul 16, 2026View HOL analysis
  43. CVE-2026-20150High
    Cisco RoomOS Security Hardening Release - Access Control Vulnerabilities
    CVSS 8.8
    Cisco/Cisco RoomOS Softwaregeneric
    PublishedJul 15, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  44. CVE-2026-45150Medium
    Zen Browser - Missing Fullscreen Security Notification Allows Origin Spoofing
    CVSS 6.3
    zen-browser/desktopgeneric
    PublishedJul 15, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  45. CVE-2026-45805High
    Penpot: MCP REPL server binds to 0.0.0.0 with unauthenticated /execute endpoint — RCE
    CVSS 8.8
    penpot/penpotgeneric
    PublishedJul 15, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  46. CVE-2026-44986Critical
    Penpot: Pre-authenticated account takeover via team-invitation token + prepare-register-profile
    CVSS 9.9
    penpot/penpotgeneric
    PublishedJul 15, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  47. CVE-2026-45806High
    Penpot: Authenticated SSRF in remote image import via create-file-media-object-from-url
    CVSS 7.7
    penpot/penpotgeneric
    PublishedJul 15, 2026First seen at HOL Jul 15, 2026Updated Jul 20, 2026View HOL analysis
  48. CVE-2026-47160Medium
    Vaultwarden: Server-side request forgery (SSRF) via Icon Endpoint Decimal/Hex/Octal IP Bypass
    CVSS 5.8
    dani-garcia/vaultwardengeneric
    PublishedJul 15, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  49. CVE-2026-47164High
    Vaultwarden: SSO Email Auto-Link Can Bind an Existing Local Account to an Attacker-Controlled IdP Identity
    CVSS 7.7
    dani-garcia/vaultwardengeneric
    PublishedJul 15, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  50. CVE-2026-47159Medium
    Vaultwarden: Authentication Flow Information Disclosure in SSO Discovery Allows Organization Enumeration and Pre-Validation Token Exposure
    CVSS 6.9
    dani-garcia/vaultwardengeneric
    PublishedJul 15, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
Page 60 of 327
Previous5859606162Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard

8,448

Critical + high

1,443

Known exploited

12

Ecosystems

Search and filter active CVEs

Filters & sort
Severity
Clear

Showing 2,951–3,000 of 16,326 active CVEs

Sorted by Published (newest)

Active CVE results

Select a result for the HOL analysis
IdentityRiskAffected softwarePublished
  1. CVE-2026-33445High
    Memory management vulnerability in Secure Access servers
    CVSS 8.7
    Absolute Security/Secure Accessgeneric
    PublishedJul 15, 2026First seen at HOL Jul 15, 2026Updated Jul 16, 2026 Fix availableView HOL analysis
  2. CVE-2026-33444Medium
    Memory management vulnerability in Secure Access servers
    CVSS 6.9
    Absolute Secutity/Secure Accessgeneric
    PublishedJul 15, 2026First seen at HOL Jul 15, 2026Updated Jul 16, 2026 Fix availableView HOL analysis
  3. CVE-2026-33443High
    Memory management error in Secure Access servers prior to 14.55
    CVSS 7.1
    Absolute Security/Secure Accessgeneric
    PublishedJul 15, 2026First seen at HOL Jul 15, 2026Updated Jul 16, 2026 Fix availableView HOL analysis
  4. CVE-2026-40958Low
    Input validation error in Secure Access clients prior to 14.55
    CVSS 3.7
    Absolute Security/Secure Accessgeneric
    PublishedJul 15, 2026First seen at HOL Jul 15, 2026Updated Jul 16, 2026 Fix availableView HOL analysis
  5. CVE-2026-45737Medium
    Argo CD: Kubernetes Secret Extraction via ArgoCD ServerSideDiff via sensitive annotations
    CVSS 6.3
    argoproj/argo-cd, github.com/argoproj/argo-cd +2generic · go
    PublishedJul 15, 2026First seen at HOL Jul 15, 2026Updated Jul 20, 2026 Fix availableView HOL analysis
  6. CVE-2026-40957High
    Frameable content vulnerability in the Secure Access server login page
    CVSS 7.5
    Absolute Security/Secure Accessgeneric
    PublishedJul 15, 2026First seen at HOL Jul 15, 2026Updated Jul 16, 2026 Fix availableView HOL analysis
  7. CVE-2026-40956Low
    Memory disclosure in Secure Access Clients
    CVSS 3.7
    Absolute Security/Secure Accessgeneric
    PublishedJul 15, 2026First seen at HOL Jul 15, 2026Updated Jul 16, 2026 Fix availableView HOL analysis
  8. CVE-2026-45738High
    Argo CD: Stored XSS in application link annotations enables developer-to-admin privilege escalation
    CVSS 7.3
    argoproj/argo-cdgeneric
    PublishedJul 15, 2026First seen at HOL Jul 15, 2026Updated Jul 16, 2026View HOL analysis
  9. CVE-2026-40955Low
    Integer underflow vulnerability in Secure Access clients
    CVSS 3.7
    Absolute Security/Secure Accessgeneric
    PublishedJul 15, 2026First seen at HOL Jul 15, 2026Updated Jul 16, 2026 Fix availableView HOL analysis
  10. CVE-2026-40954Low
    Integer underflow in Secure Access clients prior to 14.55
    CVSS 3.7
    Absolute Security/Secure Accessgeneric
    PublishedJul 15, 2026First seen at HOL Jul 15, 2026Updated Jul 16, 2026 Fix availableView HOL analysis
  11. CVE-2026-46684Critical
    DataEase: Unauthorized Command Execution Vulnerability
    CVSS 9.5
    dataease/dataeasegeneric
    PublishedJul 15, 2026First seen at HOL Jul 15, 2026Updated Jul 17, 2026View HOL analysis
  12. CVE-2026-40953Medium
    Heap overflow in Secure Access clients
    CVSS 6.7
    Absolute Security/Secure Accessgeneric
    PublishedJul 15, 2026First seen at HOL Jul 15, 2026Updated Jul 16, 2026 Fix availableView HOL analysis
  13. CVE-2026-45320High
    DataEase Data Dashboard SqlVariable transFilter Unfiltered SQL Injection
    CVSS 8.7
    dataease/dataeasegeneric
    PublishedJul 15, 2026First seen at HOL Jul 15, 2026Updated Jul 17, 2026View HOL analysis
  14. CVE-2026-45535High
    DataEase: Stored SQL Injection Vulnerability
    CVSS 8.7
    dataease/dataeasegeneric
    PublishedJul 15, 2026First seen at HOL Jul 15, 2026Updated Jul 16, 2026View HOL analysis
  15. CVE-2026-45533High
    DataEase: Path Traversal Vulnerability
    CVSS 8.3
    dataease/dataeasegeneric
    PublishedJul 15, 2026First seen at HOL Jul 15, 2026Updated Jul 17, 2026View HOL analysis
  16. CVE-2026-40952High
    Privilge misconfiguration in Secure Access installers
    CVSS 8.5
    Absolute Security/Secure Accessgeneric
    PublishedJul 15, 2026First seen at HOL Jul 15, 2026Updated Jul 16, 2026 Fix availableView HOL analysis
  17. CVE-2026-45419High
    DataEase: Arbitrary File Write Vulnerability
    CVSS 8.5
    dataease/dataeasegeneric
    PublishedJul 15, 2026First seen at HOL Jul 15, 2026Updated Jul 18, 2026View HOL analysis
  18. CVE-2026-45417High
    DataEase: SQL injection vulnerability
    CVSS 8.7
    dataease/dataeasegeneric
    PublishedJul 15, 2026First seen at HOL Jul 15, 2026Updated Jul 16, 2026View HOL analysis
  19. CVE-2026-45534Critical
    DataEase: RCE Vulnerability
    CVSS 9.0
    dataease/dataeasegeneric
    PublishedJul 15, 2026First seen at HOL Jul 15, 2026Updated Jul 16, 2026View HOL analysis
  20. CVE-2026-15895High
    OS command injection in jsii-diff in AWS jsii
    CVSS 7.8
    AWS/jsii, jsii-diffgeneric · npm
    PublishedJul 15, 2026First seen at HOL Jul 15, 2026Updated Aug 7, 2026 Fix availableView HOL analysis
  21. CVE-2026-46421Critical
    Supply chain compromise via malicious package versions (@cap-js/sqlite, @cap-js/postgres, @cap-js/db-service)
    CVSS 9.3
    @cap-js/db-service/@cap-js/db-service, cap-js/@cap-js/postgres +1generic
    PublishedJul 15, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  22. CVE-2026-26032Medium
    Apache Ivy: PackagerResolver path traversal vulnerability
    CVSS 5.4
    Apache Software Foundation/Apache Ivygeneric
    PublishedJul 15, 2026First seen at HOL Jul 15, 2026Updated Jul 16, 2026View HOL analysis
  23. CVE-2026-15746Medium
    Credential disclosure in Strands Agents Tools elasticsearch_memory tool
    CVSS 6.5
    Amazon/strands-agents-toolsgeneric
    PublishedJul 15, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  24. CVE-2026-12997High
    Gravity Forms <= 2.10.4 - Unauthenticated Arbitrary File Read via 'gform_uploaded_files' Parameter
    CVSS 7.5
    Gravity Forms/Gravity Formsgeneric
    PublishedJul 15, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  25. CVE-2026-46485High
    Dash: Users can write to config despire permissions (OIDC tested)
    CVSS 8.2
    lissy93/dashygeneric
    PublishedJul 15, 2026First seen at HOL Jul 15, 2026Updated Jul 20, 2026View HOL analysis
  26. CVE-2026-40501High
    Cherry Studio RCE via SearchService nodeIntegration Misconfiguration
    CVSS 8.8
    CherryHQ/cherry-studiogeneric
    PublishedJul 15, 2026First seen at HOL Jul 15, 2026Updated Jul 28, 2026View HOL analysis
  27. CVE-2026-10673High
    Out-of-bounds write in ADIN2111/ADIN1110 OA SPI Ethernet RX frame reassembly
    CVSS 8.3
    zephyrproject/zephyrgeneric
    PublishedJul 15, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  28. CVE-2026-12382High
    Aap-gateway: missing requestheaderstoremove allows mtls bypass via subject header spoofing
    CVSS 8.2
    Affected software not mappedEcosystem not listed
    PublishedJul 15, 2026First seen at HOL Jul 15, 2026Updated Jul 21, 2026View HOL analysis
  29. CVE-2026-20298Medium
    Sensitive Information Disclosure through the storage/passwords REST Endpoint in Splunk Enterprise
    CVSS 5.3
    Splunk/Splunk Cloud Platform, Splunk/Splunk Enterprisegeneric
    PublishedJul 15, 2026First seen at HOL Jul 16, 2026Updated Jul 16, 2026 Fix availableView HOL analysis
  30. CVE-2026-20296High
    SPL Command Safeguards Bypass through Cross-Site Request Forgery (CSRF) in Deployment Server in Splunk Enterprise
    CVSS 8.3
    Splunk/Splunk Cloud Platform, Splunk/Splunk Enterprisegeneric
    PublishedJul 15, 2026First seen at HOL Jul 15, 2026Updated Jul 16, 2026 Fix availableView HOL analysis
  31. CVE-2026-20297High
    Path Traversal through 'explicit_appname' in the App Install REST Endpoint in Splunk Enterprise
    CVSS 7.2
    Splunk/Splunk Cloud Platform, Splunk/Splunk Enterprisegeneric
    PublishedJul 15, 2026First seen at HOL Jul 15, 2026Updated Jul 16, 2026 Fix availableView HOL analysis
  32. CVE-2026-14961Medium
    CVE-2026-14961
    CVSS 6.2
    Pegatron Corp./Tdelo64.sysgeneric
    PublishedJul 15, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  33. CVE-2026-14960Critical
    CVE-2026-14960
    CVSS 9.8
    Pegatron Corp./Tdelo64.sysgeneric
    PublishedJul 15, 2026First seen at HOL Jul 15, 2026Updated Jul 16, 2026View HOL analysis
  34. CVE-2026-1563Medium
    Pega Platform versions 8.1.0 through 25.1.2 are affected by an Reflected Cross-site scripting (XSS) vulnerability in a user interface component. Requires a high privileged user with a developer role.
    CVSS 4.8
    Pegasystems/Pega Infinitygeneric
    PublishedJul 15, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  35. CVE-2026-1562Medium
    Pega Platform versions 8.1.0 through 25.1.2 are affected by an Stored Cross-site scripting (XSS) vulnerability in a user interface component. Requires a high privileged user with a developer role.
    CVSS 4.6
    Pegasystems/Pega Infinitygeneric
    PublishedJul 15, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026 Fix availableView HOL analysis
  36. CVE-2026-45793High
    Composer: Github Actions issued GITHUB_TOKEN disclosure in GitHub Actions logs
    CVSS 7.5
    composer/composergeneric
    PublishedJul 15, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  37. CVE-2026-20187High
    Cisco RoomOS Security Hardening Release - Exceptional Conditions Handling Vulnerabilities
    CVSS 7.5
    Cisco/Cisco RoomOS Softwaregeneric
    PublishedJul 15, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  38. CVE-2026-20158High
    Cisco RoomOS Security Hardening Release - Resource Lifetime Management Vulnerabilities
    CVSS 7.5
    Cisco/Cisco RoomOS Softwaregeneric
    PublishedJul 15, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  39. CVE-2026-20153High
    Cisco RoomOS Security Hardening Release - Input Validation Vulnerabilities
    CVSS 7.5
    Cisco/Cisco RoomOS Softwaregeneric
    PublishedJul 15, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  40. CVE-2026-20157High
    Cisco RoomOS Security Hardening Release - Missing Encryption Vulnerabilities
    CVSS 7.5
    Cisco/Cisco RoomOS Softwaregeneric
    PublishedJul 15, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  41. CVE-2026-20156High
    Cisco RoomOS Security Hardening Release - Buffer Management Vulnerabilities
    CVSS 8.1
    Cisco/Cisco RoomOS Softwaregeneric
    PublishedJul 15, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  42. CVE-2026-20146Medium
    Cisco Identity Services Engine Path Traversal Vulnerability
    CVSS 5.5
    Cisco/Cisco ISE Passive Identity Connector, Cisco/Cisco Identity Services Engine Softwaregeneric
    PublishedJul 15, 2026First seen at HOL Jul 15, 2026Updated Jul 16, 2026View HOL analysis
  43. CVE-2026-20150High
    Cisco RoomOS Security Hardening Release - Access Control Vulnerabilities
    CVSS 8.8
    Cisco/Cisco RoomOS Softwaregeneric
    PublishedJul 15, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  44. CVE-2026-45150Medium
    Zen Browser - Missing Fullscreen Security Notification Allows Origin Spoofing
    CVSS 6.3
    zen-browser/desktopgeneric
    PublishedJul 15, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  45. CVE-2026-45805High
    Penpot: MCP REPL server binds to 0.0.0.0 with unauthenticated /execute endpoint — RCE
    CVSS 8.8
    penpot/penpotgeneric
    PublishedJul 15, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  46. CVE-2026-44986Critical
    Penpot: Pre-authenticated account takeover via team-invitation token + prepare-register-profile
    CVSS 9.9
    penpot/penpotgeneric
    PublishedJul 15, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  47. CVE-2026-45806High
    Penpot: Authenticated SSRF in remote image import via create-file-media-object-from-url
    CVSS 7.7
    penpot/penpotgeneric
    PublishedJul 15, 2026First seen at HOL Jul 15, 2026Updated Jul 20, 2026View HOL analysis
  48. CVE-2026-47160Medium
    Vaultwarden: Server-side request forgery (SSRF) via Icon Endpoint Decimal/Hex/Octal IP Bypass
    CVSS 5.8
    dani-garcia/vaultwardengeneric
    PublishedJul 15, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  49. CVE-2026-47164High
    Vaultwarden: SSO Email Auto-Link Can Bind an Existing Local Account to an Attacker-Controlled IdP Identity
    CVSS 7.7
    dani-garcia/vaultwardengeneric
    PublishedJul 15, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
  50. CVE-2026-47159Medium
    Vaultwarden: Authentication Flow Information Disclosure in SSO Discovery Allows Organization Enumeration and Pre-Validation Token Exposure
    CVSS 6.9
    dani-garcia/vaultwardengeneric
    PublishedJul 15, 2026First seen at HOL Jul 15, 2026Updated Jul 15, 2026View HOL analysis
Page 60 of 327
Previous5859606162Next
How this catalog works

Active means a non-withdrawn CVE List record with a validated alias, English description, publication date, and source reference. Published is the CVE Program date; First seen at HOL is when this feed first indexed the record; Modified and Source checked describe later feed activity. Severity uses the reported source value when present, otherwise a valid CVSS score supplies the displayed band. Unmapped records do not imply package coverage.

Put Guard beside your supply-chain workflow.

Explore HOL Guard